An XSS vulnerability was discovered in the upload file(s) process of imartinez/privategpt v0.5.0. Attackers can upload malicious SVG files, which execute JavaScript when victims click on the file link. This can lead to user data theft, session hijacking, malware distribution, and phishing attacks.
Metrics
Affected Vendors & Products
References
History
Thu, 17 Jul 2025 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Pribai
Pribai privategpt |
|
CPEs | cpe:2.3:a:pribai:privategpt:0.5.0:*:*:*:*:*:*:* | |
Vendors & Products |
Pribai
Pribai privategpt |
|
Metrics |
cvssV3_1
|
Thu, 20 Mar 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 20 Mar 2025 10:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An XSS vulnerability was discovered in the upload file(s) process of imartinez/privategpt v0.5.0. Attackers can upload malicious SVG files, which execute JavaScript when victims click on the file link. This can lead to user data theft, session hijacking, malware distribution, and phishing attacks. | |
Title | Stored XSS in imartinez/privategpt | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV3_0
|

Status: PUBLISHED
Assigner: @huntr_ai
Published: 2025-03-20T10:09:21.980Z
Updated: 2025-03-20T18:55:55.477Z
Reserved: 2024-08-20T19:38:40.578Z
Link: CVE-2024-8029

Updated: 2025-03-20T17:51:16.674Z

Status : Analyzed
Published: 2025-03-20T10:15:39.870
Modified: 2025-07-17T15:56:07.520
Link: CVE-2024-8029

No data.